Fake Party Invites Lure Victims Into Installing Malicious Remote Access Tools
A recent social engineering campaign has been identified targeting Windows users in the UK. This operation uses fake event invitations to install ScreenConnect, a legitimate remote access tool, which attackers exploit to gain full control over targeted…
A recent social engineering campaign has been identified targeting Windows users in the UK. This operation uses fake event invitations to install ScreenConnect, a legitimate remote access tool, which attackers exploit to gain full control over targeted systems.
The attack initiates with emails that appear as personal invitations from trusted contacts. These emails often originate from compromised legitimate accounts, enhancing their credibility. Upon clicking the included link, users are redirected to download a file named RSVPPartyInvitationCard.msi . This file, instead of containing an actual invitation, installs the ScreenConnect Client.
Upon execution, the MSI file uses msiexec.exe to install ScreenConnect binaries in the directory C:\Program Files (x86)\ScreenConnect Client . A Windows service with a random identifier is created, and multiple .NET-based components are installed. These actions occur without any visible indication to the user, granting attackers remote access similar to IT personnel.
The ScreenConnect client establishes encrypted connections to relay servers, allowing attackers to monitor the screen, control input devices, transfer files, and maintain persistent access across system reboots. The software's legitimate usage by IT support teams can obscure its malicious presence, with victims often noticing unusual behaviors like unexplained cursor movements or unfamiliar processes.
A recent social engineering campaign has been identified targeting Windows users in the UK.
Users should be cautious of unsolicited invitations that prompt software downloads. It is advised never to execute MSI files from unknown sources and to verify any invitation through direct communication channels. In case of suspected compromise, disconnect from the internet, uninstall ScreenConnect, perform a full security scan, and change passwords using a secure device.
Organizations should monitor for unauthorized ScreenConnect installations, limit the execution of MSI files, classify remote support tools as high-risk, and inform users that legitimate invitations do not require software installation.
Effective endpoint protection is crucial to detect newly installed remote access tools, preventing unauthorized access through seemingly innocuous channels.
Based on reporting by GBHackers.
